The Fourthline Team
Why Fraud Operations Don’t Scale, and What Leading Financial Institutions Do Differently
Why Fraud Operations Don’t Scale, and What Leading Financial Institutions Do Differently
If you run a fraud operation, your team is likely working harder than ever. Thanks to AI, the fraud landscape is evolving faster than many organisations can expect, leaving them constantly playing catch-up.
This trend affects businesses in many ways, but perhaps most materially in their bottom lines. According to a 2024 report by Deloitte, "AI-enabled fraud losses projected to reach $40 billion by 2027." Despite these alarming losses, research conducted by the Association of Certified Fraud Examiners (ACFE) found that "only 7% of organisations say they are more than moderately prepared to detect or prevent AI-fuelled fraud"." Without the ability to effectively scale their fraud operations, financial companies will continue to suffer financial impacts, and to meet their regulatory objectives.
Here’s the thing: it’s absolutely possible to build fraud-detection infrastructure that grows with the evolving threat climate. We’ve been helping organisations do this from the start. It takes some strategic planning, and a willingness to invest in intelligent systems that can learn and grow with your business. Here, we’ll dive into what some institutions are doing wrong, and what the ones doing it right do differently.
The manual review trap
It’s tempting to prioritise manual review for many reasons. Fraud is scary, and the risks it puts your organisation at are real. And manual review can work well at a smaller institution with lower volumes.
However, when you’re dealing with huge amounts of cases, the manual model simply can’t hold up. Here are some clear issues we see when manual review runs the show:
1. Inconsistency: Human error is a real thing. Two individual agents reviewing the same case will not always reach the same decision. Furthermore, one human’s capacity might vary based on their experience, fatigue, or caseload pressure.
2. Pace: Manual review is considerably slower than other solutions, which (when applied at scale) could impact customer experience and conversion rates.
3. Cost: Hiring enough staff to handle your increasing volume of cases means your costs will invariably rise.
4. False sense of security. High manual review rates can mask low automation quality. This means you might not know that your systems are failing until it’s too late.
5. Reactivity. Manual reviewers respond to what's in their queue. They can't proactively detect patterns across cases the way a data-driven system can, which means emerging fraud trends are identified late — if at all.
6. Pressure. When queues build, the pressure to clear cases fast increases, which is exactly when fraud slips through.
7. Scale. In the age of such rapid technical advancement, fraud volume will almost always grow faster than headcount. As queues build, average handling time increases and decision quality degrades.
Another problem is that the decisions most likely to hurt a fraud operation are often made outside the fraud team entirely, whether that’s in Product, UX, or in commercial negotiations. Even a small configuration change can reduce document fraud catch rates by a large portion.
FAR, FRR, and the trade-offs nobody talks about
If manual review is the operational problem, the way most institutions measure fraud performance is the strategic one.
Most fraud operations track one of two metrics obsessively: False Acceptance Rate (how often fraudulent cases are incorrectly approved) and False Rejection Rate (how often legitimate customers are incorrectly turned away). The problem is that optimising for one almost always comes at the expense of the other. Tighten controls to reduce FAR, and FRR rises. Loosen them to improve conversion, and FAR climbs.
Every institution has to make their own choice as to where they sit on the FAR/FRR continuum. A neobank onboarding at scale will likely tolerate more risk than a legacy bank. The problem isn't the choice itself. It's that most institutions make it implicitly rather than deliberately.
Furthermore, once the FAR/FRR metrics are set, institutions often treat this decision as fixed. But the most effective fraud operations manage it dynamically, adjusting in real time based on risk signals rather than operating to a single static threshold.
The instinct is to build a smarter model. It’s the correct instinct, but only if it's done right. Most institutions make the mistake of replacing one problem with another one: a single AI model, deployed to solve a specific fraud type, that gets outsmarted faster than it can be updated.
The single-model problem
As we've observed across our work with financial institutions over the years, relying on a single model for a specific fraud method is almost never enough. These models are quickly circumvented, leading to a reactive cycle of updates. This in turn means that fraud teams are always one step behind. Fraud patterns that were invisible to document authentication models, such as professionally manipulated documents that pass visual checks, continue to pass verification until they are caught later on. At that point, they’ve likely caused some significant damage.
The alternative is a multi-layered AI system where no single point of failure exists. Each layer catches what the previous one missed. The system improves continuously rather than updating reactively.
Read more on how multi-layered AI systems protect companies from deepfake fraud.
How leading institutions scale their fraud operations
The businesses that scale fraud operations effectively share four behaviours that distinguish them from those that don't. Here are some common traits we’ve seen in companies who manage to grow their fraud functions effectively.
They catch fraud at multiple points, not just one.
Catching bad actors during onboarding is paramount in fraud prevention. This is called “ex-ante detection,” and it’s where many companies centre their fraud efforts. But it’s not enough on its own to keep your institution safe. There is also something called “ex-post detection,” which is catching fraud after a customer has successfully completed onboarding.
For companies, especially those looking to grow, it’s critical to invest in catching fraud that slipped through that first interaction. Why? For one thing, you’re improving your operations while training your system. Every fraudster caught this way gets added to your fraud database, which makes your onboarding detection smarter, which in turn improves your process over time.
Retrospective analysis, facial recognition screening, network investigation, and geolocation cross-referencing all help to identify fraudulent accounts later on in the customer journey. In our experience, this second layer catches a meaningful proportion of fraud that may otherwise go entirely undetected.
They build feedback loops between the people catching fraud and the systems doing it.
In a well-functioning fraud-detection system, the issues or patterns that human agents identify don't stay with the agents. Instead, they get fed back to product and engineering teams so their models can be updated quickly. Without that loop, a widening gap opens between what fraud agents are seeing on the ground and what the company’s automated systems are configured to catch.
They set their FAR/FRR balance deliberately — and manage it dynamically.
As we’ve learned, every institution has to choose where they sit on the FAR/FRR spectrum. But this decision, far from being static, is dynamic, and can and should change over time. The most astute institutions monitor FAR/FRR continuously and adjust in real time based on risk signals when the balance shifts in any direction, rather than retaining the status quo regardless of what's happening.
They combine their own data with the right vendor capabilities
The institutions that scale fraud detection most effectively don't choose between building and buying. They do both. An institution's own customer history, transaction patterns, and risk knowledge are signals unique to their business. But the right vendor brings proprietary models, cross-client fraud intelligence, and investigation and audit capabilities that would take most companies years to build on their own. When it comes to fighting fraud at scale, it’s essential to understand what you can build in house and what makes more sense to outsource.
The conversion trap
It’s worth taking a moment to acknowledge how the business side of things lines up with fraud risk. Balancing fraud prevention with commercial success is difficult to get right — we’ve seen it firsthand. Removing friction steps, disabling geolocation checks, or relaxing document requirements might improve conversion rates, but increase fraud to an unacceptable degree.
The good news is that conversion and fraud prevention don't necessarily have to be in tension with one another. The move here is a dynamic, risk-based approach, one where security requirements get adjusted based on device signals, location, and behavioural data. In this type of framework, low-risk customers move through the system quickly, while high-risk customers trigger additional verification steps. This approach simultaneously reduces fraud losses and increases legitimate customer conversion.
The bottom line
Faud operations hardly ever fail because of bad people. They fail because of bad architecture and a lack of foresight: too much manpower tied up in caseloads, single models, and technical or commercial decisions made without input from fraud teams.
The institutions we’ve worked with that have scaled effectively treat fraud detection as a system. They invest in ex-post detection as seriously as ex-ante. They build and integrate feedback loops that make their models smarter over time. And they understand that the conversion-versus-fraud trade-off is a false choice.
Scale your fraud operations with Fourthline
Fourthline is a purpose-built identity verification and compliance platform for regulated financial institutions, supervised by the Dutch Central Bank. Our fraud detection infrastructure combines layered, proprietary AI models for ex-ante detection with a dedicated Anti-Financial Crime team for ex-post investigation. Every insight feeds back into our models. Our proprietary Fraud Prevention List gives institutions a detection signal that compounds over time. If you’re looking to grow your fraud prevention function and need the tools to do so, we can help.
FAQs
What is the difference between FAR and FRR in fraud detection?
False Acceptance Rate (FAR) measures how often a fraud operation incorrectly approves a fraudulent case. False Rejection Rate (FRR) measures how often it incorrectly rejects a legitimate one. Most fraud operations optimise for one at the expense of the other: reducing FAR by tightening controls increases FRR, and vice versa.
What is ex-post fraud detection?
Ex-post fraud detection refers to identifying fraud that has already passed the initial onboarding or verification flow. Unlike ex-ante detection, which catches fraud in real time during onboarding, ex-post detection uses retrospective analysis, network investigation, and facial recognition screening to identify fraudulent accounts after the fact.
If you run a fraud operation, your team is likely working harder than ever. Thanks to AI, the fraud landscape is evolving faster than many organisations can expect, leaving them constantly playing catch-up.
This trend affects businesses in many ways, but perhaps most materially in their bottom lines. According to a 2024 report by Deloitte, "AI-enabled fraud losses projected to reach $40 billion by 2027." Despite these alarming losses, research conducted by the Association of Certified Fraud Examiners (ACFE) found that "only 7% of organisations say they are more than moderately prepared to detect or prevent AI-fuelled fraud"." Without the ability to effectively scale their fraud operations, financial companies will continue to suffer financial impacts, and to meet their regulatory objectives.
Here’s the thing: it’s absolutely possible to build fraud-detection infrastructure that grows with the evolving threat climate. We’ve been helping organisations do this from the start. It takes some strategic planning, and a willingness to invest in intelligent systems that can learn and grow with your business. Here, we’ll dive into what some institutions are doing wrong, and what the ones doing it right do differently.
The manual review trap
It’s tempting to prioritise manual review for many reasons. Fraud is scary, and the risks it puts your organisation at are real. And manual review can work well at a smaller institution with lower volumes.
However, when you’re dealing with huge amounts of cases, the manual model simply can’t hold up. Here are some clear issues we see when manual review runs the show:
1. Inconsistency: Human error is a real thing. Two individual agents reviewing the same case will not always reach the same decision. Furthermore, one human’s capacity might vary based on their experience, fatigue, or caseload pressure.
2. Pace: Manual review is considerably slower than other solutions, which (when applied at scale) could impact customer experience and conversion rates.
3. Cost: Hiring enough staff to handle your increasing volume of cases means your costs will invariably rise.
4. False sense of security. High manual review rates can mask low automation quality. This means you might not know that your systems are failing until it’s too late.
5. Reactivity. Manual reviewers respond to what's in their queue. They can't proactively detect patterns across cases the way a data-driven system can, which means emerging fraud trends are identified late — if at all.
6. Pressure. When queues build, the pressure to clear cases fast increases, which is exactly when fraud slips through.
7. Scale. In the age of such rapid technical advancement, fraud volume will almost always grow faster than headcount. As queues build, average handling time increases and decision quality degrades.
Another problem is that the decisions most likely to hurt a fraud operation are often made outside the fraud team entirely, whether that’s in Product, UX, or in commercial negotiations. Even a small configuration change can reduce document fraud catch rates by a large portion.
FAR, FRR, and the trade-offs nobody talks about
If manual review is the operational problem, the way most institutions measure fraud performance is the strategic one.
Most fraud operations track one of two metrics obsessively: False Acceptance Rate (how often fraudulent cases are incorrectly approved) and False Rejection Rate (how often legitimate customers are incorrectly turned away). The problem is that optimising for one almost always comes at the expense of the other. Tighten controls to reduce FAR, and FRR rises. Loosen them to improve conversion, and FAR climbs.
Every institution has to make their own choice as to where they sit on the FAR/FRR continuum. A neobank onboarding at scale will likely tolerate more risk than a legacy bank. The problem isn't the choice itself. It's that most institutions make it implicitly rather than deliberately.
Furthermore, once the FAR/FRR metrics are set, institutions often treat this decision as fixed. But the most effective fraud operations manage it dynamically, adjusting in real time based on risk signals rather than operating to a single static threshold.
The instinct is to build a smarter model. It’s the correct instinct, but only if it's done right. Most institutions make the mistake of replacing one problem with another one: a single AI model, deployed to solve a specific fraud type, that gets outsmarted faster than it can be updated.
The single-model problem
As we've observed across our work with financial institutions over the years, relying on a single model for a specific fraud method is almost never enough. These models are quickly circumvented, leading to a reactive cycle of updates. This in turn means that fraud teams are always one step behind. Fraud patterns that were invisible to document authentication models, such as professionally manipulated documents that pass visual checks, continue to pass verification until they are caught later on. At that point, they’ve likely caused some significant damage.
The alternative is a multi-layered AI system where no single point of failure exists. Each layer catches what the previous one missed. The system improves continuously rather than updating reactively.
Read more on how multi-layered AI systems protect companies from deepfake fraud.
How leading institutions scale their fraud operations
The businesses that scale fraud operations effectively share four behaviours that distinguish them from those that don't. Here are some common traits we’ve seen in companies who manage to grow their fraud functions effectively.
They catch fraud at multiple points, not just one.
Catching bad actors during onboarding is paramount in fraud prevention. This is called “ex-ante detection,” and it’s where many companies centre their fraud efforts. But it’s not enough on its own to keep your institution safe. There is also something called “ex-post detection,” which is catching fraud after a customer has successfully completed onboarding.
For companies, especially those looking to grow, it’s critical to invest in catching fraud that slipped through that first interaction. Why? For one thing, you’re improving your operations while training your system. Every fraudster caught this way gets added to your fraud database, which makes your onboarding detection smarter, which in turn improves your process over time.
Retrospective analysis, facial recognition screening, network investigation, and geolocation cross-referencing all help to identify fraudulent accounts later on in the customer journey. In our experience, this second layer catches a meaningful proportion of fraud that may otherwise go entirely undetected.
They build feedback loops between the people catching fraud and the systems doing it.
In a well-functioning fraud-detection system, the issues or patterns that human agents identify don't stay with the agents. Instead, they get fed back to product and engineering teams so their models can be updated quickly. Without that loop, a widening gap opens between what fraud agents are seeing on the ground and what the company’s automated systems are configured to catch.
They set their FAR/FRR balance deliberately — and manage it dynamically.
As we’ve learned, every institution has to choose where they sit on the FAR/FRR spectrum. But this decision, far from being static, is dynamic, and can and should change over time. The most astute institutions monitor FAR/FRR continuously and adjust in real time based on risk signals when the balance shifts in any direction, rather than retaining the status quo regardless of what's happening.
They combine their own data with the right vendor capabilities
The institutions that scale fraud detection most effectively don't choose between building and buying. They do both. An institution's own customer history, transaction patterns, and risk knowledge are signals unique to their business. But the right vendor brings proprietary models, cross-client fraud intelligence, and investigation and audit capabilities that would take most companies years to build on their own. When it comes to fighting fraud at scale, it’s essential to understand what you can build in house and what makes more sense to outsource.
The conversion trap
It’s worth taking a moment to acknowledge how the business side of things lines up with fraud risk. Balancing fraud prevention with commercial success is difficult to get right — we’ve seen it firsthand. Removing friction steps, disabling geolocation checks, or relaxing document requirements might improve conversion rates, but increase fraud to an unacceptable degree.
The good news is that conversion and fraud prevention don't necessarily have to be in tension with one another. The move here is a dynamic, risk-based approach, one where security requirements get adjusted based on device signals, location, and behavioural data. In this type of framework, low-risk customers move through the system quickly, while high-risk customers trigger additional verification steps. This approach simultaneously reduces fraud losses and increases legitimate customer conversion.
The bottom line
Faud operations hardly ever fail because of bad people. They fail because of bad architecture and a lack of foresight: too much manpower tied up in caseloads, single models, and technical or commercial decisions made without input from fraud teams.
The institutions we’ve worked with that have scaled effectively treat fraud detection as a system. They invest in ex-post detection as seriously as ex-ante. They build and integrate feedback loops that make their models smarter over time. And they understand that the conversion-versus-fraud trade-off is a false choice.
Scale your fraud operations with Fourthline
Fourthline is a purpose-built identity verification and compliance platform for regulated financial institutions, supervised by the Dutch Central Bank. Our fraud detection infrastructure combines layered, proprietary AI models for ex-ante detection with a dedicated Anti-Financial Crime team for ex-post investigation. Every insight feeds back into our models. Our proprietary Fraud Prevention List gives institutions a detection signal that compounds over time. If you’re looking to grow your fraud prevention function and need the tools to do so, we can help.
FAQs
What is the difference between FAR and FRR in fraud detection?
False Acceptance Rate (FAR) measures how often a fraud operation incorrectly approves a fraudulent case. False Rejection Rate (FRR) measures how often it incorrectly rejects a legitimate one. Most fraud operations optimise for one at the expense of the other: reducing FAR by tightening controls increases FRR, and vice versa.
What is ex-post fraud detection?
Ex-post fraud detection refers to identifying fraud that has already passed the initial onboarding or verification flow. Unlike ex-ante detection, which catches fraud in real time during onboarding, ex-post detection uses retrospective analysis, network investigation, and facial recognition screening to identify fraudulent accounts after the fact.
Solutions
Solutions
Fourthline has been certified by EY CertifyPoint to ISO/IEC27001:2022 with certification number 2021-039.
Copyright © 2026 - Fourthline B.V. - All rights reserved.
Fourthline has been certified by EY CertifyPoint to ISO/IEC27001:2022 with certification number 2021-039.
Copyright © 2026 - Fourthline B.V. - All rights reserved.